CVE-2026-66467

WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability

Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.


We have discovered 219 live websites that are affected by CVE-2026-66467.

Run a Free Instant Scan




Affected Software

Product  FluentCommunity
Category Wordpress Plugins
Vulnerable Domains219 live websites (100% of FluentCommunity install base)
Vulnerable Versions
  • from 0 through 2.7.5
Vulnerable Versions Count14 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • Septio Noerdiansyah | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66467
United States95 websites



Germany28 websites
Cyprus15 websites
Netherlands12 websites
France11 websites
Canada7 websites
GB6 websites
Spain4 websites
Poland4 websites
Denmark4 websites

Website Distribution by TLD

Number of websites using CVE-2026-66467
.com115 websites
.org16 websites
.de16 websites
.nl11 websites
.fr4 websites
.net4 websites
.dk4 websites
.ca3 websites
.pl3 websites
.be2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66467

Top websites that are affected by CVE-2026-66467. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********************.com Thailand**,***
****************.de Germany**,***
*******.com United States***,***
***********.com GB***,***
****************.org United States***,***
*****.com United States***,***
****.com France***,***
****************.de Germany***,***
**********.nl Netherlands***,***
*****************.com United States***,***
See full domain list

FAQ

CVE-2026-66467 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in FluentCommunity
A total of 219 websites have been identified as vulnerable to CVE-2026-66467, based on global website indexing conducted by WebTechSurvey.
The FluentCommunity is affected by the CVE-2026-66467 vulnerability.
FluentCommunity versions up to and including 2.7.5 are vulnerable to CVE-2026-66467.